PHP / OpenSSL versions


(Gary) #1

Hi,

I am running FPBX 14 and was looking to update to 15. However, I note that the PHP and OpenSSL versions are old and deprecated introducing the potential for security risks.

In fact, there is an update to at least OpenSSL 1.0.2u that Yum will not install (currently on 1.0.2k-fips) and with PHP on 5.6.40, deprecate in 2018 I believe, I think we are running a potentially insecure system… even with the upgrade to 15

Happy to be proven wrong - although security scanners WILL pick this up.

What is the plan to sort this out?

Thanks all

Gary


(Lorne Gaetz) #2

FreePBX 16 will be based on Centos 8 and will support PHP 7. Timelines are not too tight yet, but expect a 16 beta in the spring.